mirror of
https://github.com/anotherhadi/sec-notes.git
synced 2026-10-05 15:48:25 +02:00
1.6 KiB
1.6 KiB
title, description, tags, publishDate
| title | description | tags | publishDate | |||
|---|---|---|---|---|---|---|
| FTP | Enumeration, exploitation and post-exploitation techniques for FTP servers. |
|
2026-04-29 |
FTP runs on port 21 (control) and uses a secondary data channel (port 20 for active, ephemeral port for passive). Common implementations: vsftpd, ProFTPD, Pure-FTPd, FileZilla Server, IIS FTP.
Enumeration
Banner grabbing
nc -nv $IP 21
ftp $IP
The banner often reveals the software version: cross-reference with CVE databases.
Nmap
nmap -sV -p 21 $IP
nmap -p 21 --script ftp-* $IP
Key scripts:
ftp-anon: checks anonymous loginftp-bounce: tests for FTP bounce attackftp-brute: brute-force credentialsftp-syst: retrieves system info
Anonymous Login
ftp $IP
# Username: anonymous
# Password: <empty> or anonymous@
If allowed, list and download everything:
ls -la
mget *
Check for writable directories: you may be able to upload a webshell if FTP root overlaps with a web root.
Brute Force
hydra -l $user -P ~/wordlists/rockyou.txt ftp://$IP
medusa -h $IP -u $user -P ~/wordlists/rockyou.txt -M ftp
Try default credentials first: admin:admin, ftp:ftp, user:password.